Junglewise Threat Intelligence

CVE-2026-17580: wplakeorg Advanced Views sensitive information exposure in REST API

CVE-2026-17580 · Severity: medium · CVSS 6.5 · Published 2026-08-01

Executive brief

The Advanced Views plugin for WordPress, which helps site owners display custom data and product information, contains a security flaw that allows unauthorized users to view sensitive administrative content. An attacker with a basic user account (such as a subscriber) could access internal template code, styling, and technical variables that are normally restricted to site administrators. This exposure could reveal proprietary design logic or technical details that assist in further attacks against the website.

Technical details

The Advanced Views plugin for WordPress is vulnerable to Sensitive Information Exposure (CWE-862) in all versions up to and including 3.9.1. The flaw exists within the 'register_rest_routes' implementation, where insufficient authorization checks allow authenticated users with minimal privileges (Subscriber and above) to query REST API endpoints. By exploiting this, an attacker can retrieve sensitive admin-authored editor content, including template markup, CSS, JavaScript, and PHP controller variables for any 'Layout' or 'Post Selection' post type. A patch has been released in version 3.9.2 to address these authorization gaps.

Affected products

  • wplakeorg Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… up to, and including, 3.9.1

Timeline

  • 2026-08-01: disclosed
  • 2026-08-01: advisory

References

Related threats